Operational Security Capabilities for IP Network Infrastructure

7
Operational Security Capabilities for IP Network Infrastructure IETF 64 Vancouver, BC, Canada November 2005

description

Operational Security Capabilities for IP Network Infrastructure. IETF 64 Vancouver, BC, Canada November 2005. Agenda. 1850-1852: Agenda bashing / blue sheets / scribe discovery 1852-1900: document status (R.Callon) 1900-1910: draft-ietf-opsec-filter-caps-00 (Morrow/Callon) - PowerPoint PPT Presentation

Transcript of Operational Security Capabilities for IP Network Infrastructure

Page 1: Operational Security Capabilities for IP Network Infrastructure

Operational Security Capabilities for IP Network Infrastructure

IETF 64

Vancouver, BC, Canada

November 2005

Page 2: Operational Security Capabilities for IP Network Infrastructure

Agenda1850-1852: Agenda bashing / blue sheets / scribe discovery

1852-1900: document status (R.Callon)

1900-1910: draft-ietf-opsec-filter-caps-00 (Morrow/Callon)

1910-1920: draft-bonica-opsec-nmasc-00 (R.Bonica)

1920-1930: draft-callon-misc-cap-00.txt (R.Callon)

1930-1940: draft-ietf-bmwg-bench-meth-ebgp-00 and

draft-ietf-bmwg-bench-meth-opsec-00 (S.Poretsky)

1940-1950: draft-zhao-opsec-routing-capabilities-00

(M.Fuyou)

Page 3: Operational Security Capabilities for IP Network Infrastructure

WG Document Status• Framework

<draft-ietf-opsec-framework-01.txt>– Updated to avoid timeout– Further update in progress

• minor edits• examples of message modification &

deletion attacks• additional references

Page 4: Operational Security Capabilities for IP Network Infrastructure

WG Document Status• Survey of Security Efforts and Documents

<draft-ietf-opsec-efforts-01.txt>– Stable, in good shape

• Packet Filtering Capabilities<draft-ietf-opsec-filter-caps-00.txt>– Updated, presentation to follow

Page 5: Operational Security Capabilities for IP Network Infrastructure

WG Document Status• Current Practices

– draft-ietf-opsec-current-practices-02.txt

• Modifications from 01 version– Modified threat model section– Added filtering section– Added some IPv6 information

• Question for working group– Should Appendix B (protocol specific attacks) have

more details on individual attacks listed?– More detail on IPv6 required? What?– Anything missing?

Page 6: Operational Security Capabilities for IP Network Infrastructure

New Documents• Three new documents have been brought

to the working group– Network Management Access Capabilities

(aka in-band and out-of-band caps)– Miscellaneous Capabilities– Routing Control Plane Capabilities

• Presentations to follow on each

Page 7: Operational Security Capabilities for IP Network Infrastructure

Agenda1850-1852: Agenda bashing / blue sheets / scribe discovery

1852-1900: document status (R.Callon)

1900-1910: draft-ietf-opsec-filter-caps-00 (Morrow/Callon)

1910-1920: draft-bonica-opsec-nmasc-00 (R.Bonica)

1920-1930: draft-callon-misc-cap-00.txt (R.Callon)

1930-1940: draft-ietf-bmwg-bench-meth-ebgp-00 and

draft-ietf-bmwg-bench-meth-opsec-00 (S.Poretsky)

1940-1950: draft-zhao-opsec-routing-capabilities-00

(M.Fuyou)